EU Privacy Law EU/EEA

DSA Compliance for Platforms: Obligations by Tier and Where They Touch Privacy

Digital Services Act obligations for hosting services, online platforms, and VLOPs: notice-and-action, ad transparency, minors' protection, and enforcement so far.

Regulation

Regulation (EU) 2022/2065 (Digital Services Act)

Max Penalty

Up to 6% of global annual turnover

Enforcing Authority

European Commission (VLOPs/VLOSEs) and national Digital Services Coordinators

Official Source

eur-lex.europa.eu

Executive Summary

  • The DSA (Regulation 2022/2065) applies in full since 17 February 2024, imposing tiered duties on intermediaries: hosting services, online platforms, and very large platforms and search engines (45+ million EU users).
  • Platform-tier duties include notice-and-action for illegal content, statements of reasons for moderation decisions, complaint systems, ad transparency, and a ban on dark patterns.
  • Two prohibitions are pure privacy law: no advertising targeted by profiling using special category data (Article 26(3)), and no profiling-based ads to minors (Article 28).
  • VLOPs add systemic risk assessments, independent yearly audits, researcher data access, and recommender transparency.
  • The Commission enforces directly against VLOPs and has opened proceedings against X, TikTok, Meta, AliExpress, and Temu, with fines up to 6% of global turnover available.

The Digital Services Act rebuilt the EU’s rules for online intermediaries, in full force since 17 February 2024. Its heart is accountability for content moderation and advertising, but several of its sharpest provisions are privacy rules wearing platform-regulation clothes: bans on sensitive-data ad targeting, bans on profiling ads to minors, recommender transparency, and the dark pattern prohibition. If you operate a service where users post content that others see, some tier of the DSA applies to you.

RegulationRegulation (EU) 2022/2065 (DSA)
Fully applicable since17 February 2024
Max penalty6% of global annual turnover
Enforcing authorityEuropean Commission (VLOPs); national Digital Services Coordinators
Official textEUR-Lex CELEX 32022R2065

Duties by tier

All intermediaries: designate a point of contact and, for non-EU providers, an EU legal representative; publish clear terms including moderation policies; report transparency data.

Hosting services add notice-and-action: a mechanism for anyone to flag illegal content, diligent processing, and a statement of reasons to affected users for removals and restrictions.

Online platforms (hosting plus public dissemination) carry the visible layer: internal complaint handling and out-of-court dispute settlement, measures against abusive notifiers, trusted flagger priority, marketplace trader traceability, no dark patterns (Article 25), ad labeling with targeting disclosure (Article 26), recommender system transparency in terms (Article 27), and protection of minors (Article 28). Micro and small enterprises are exempt from most platform-tier duties.

VLOPs and VLOSEs add the systemic tier: annual assessments of systemic risks (illegal content, fundamental rights, elections, minors’ safety), mitigation measures, independent audits, a non-profiling recommender option, researcher data access (Article 40), ad repositories, and crisis response duties.

The privacy core

Three provisions do data protection work directly. Article 26(3) prohibits showing ads based on profiling with GDPR special category data, ending sensitive-interest targeting regardless of consent. Article 28(2) prohibits profiling-based advertising to users the platform is aware with reasonable certainty are minors. And Article 27 forces recommender transparency: the main parameters of ranking, and options to change them, must be in the terms. Each duplicates or extends GDPR ground covered in our children’s data guide and dark patterns guide, and the deeper transparency duties are covered in the algorithmic transparency guide.

Enforcement is running

The Commission moved quickly against designated platforms: formal proceedings against X (ad repository, verification design, data access), TikTok (minors’ protection, the rewards program, which TikTok withdrew from the EU), Meta (ads transparency, minors), and marketplaces AliExpress and Temu. National coordinators handle the long tail. For a mid-size platform, the pragmatic order is: confirm your tier, stand up notice-and-action with statements of reasons, fix ad labeling and any profiling of minors, and align the consent and tracking layer, which you can verify with a free scan.

Frequently Asked Questions

Who does the DSA apply to?

All intermediary services offered to EU users, tiered by function and size: mere conduits and caching services, hosting services, online platforms that disseminate user content publicly, and very large online platforms and search engines above 45 million average monthly EU users.

What is a VLOP?

A very large online platform: one designated by the Commission after reporting 45 million or more average monthly active EU users. Designated services include the major social networks, marketplaces, app stores, and adult platforms; VLOPs carry the heaviest duties and pay a supervisory fee.

What are the DSA's advertising rules?

Ads must be labeled as ads, with the advertiser identified and meaningful information about targeting parameters available (Article 26). Targeting based on profiling with special category data is banned, and all profiling-based targeting of minors is banned (Article 28).

Does the DSA require monitoring all user content?

No. Article 8 preserves the no-general-monitoring principle. The model is notice-and-action: platforms must process illegal-content notices diligently, explain moderation decisions with statements of reasons, and offer complaint and out-of-court dispute options.

How is the DSA enforced?

The Commission directly supervises VLOPs and VLOSEs; national Digital Services Coordinators handle everything else. Fines reach 6% of global annual turnover. Proceedings are already running against several designated platforms over ads transparency, minors' protection, and dark patterns.

Regulatory Crosswalk

GDPREU AI ActePrivacy Directive

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.